The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.
| Software | From | Fixed in |
|---|---|---|
| pixelite / events_manager | - | 5.9.5.x |